IP Library Granted Patent US 11,979,370
Granted Patent B2
US 11,979,370 · App. 16/412,687 · Granted May 7, 2024

Event-driven malware detection for mobile devices

Inventor: Sean Patrick McDonald (Milsons Point, AU)
Assignee: Sophos Limited
H04L63/02G06F21/52H04L63/10H04L63/145G06F2221/2133H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,979,370
App. No.
16/412,687
Granted
May 7, 2024
Kind
B2
Abstract

Securing a mobile device against malware may include an analysis of events executing on the mobile device to detect and identify unexpected behaviors and events, and further determining whether these unexpected behaviors and events are authorized or unauthorized. Specific runtime events may be compared to patterns of expected user input/interaction on the mobile device, or generalized background behavior patterns occurring without user input/interaction, to determine whether events are expected or unexpected, and/or to determine whether events are authorized or potentially malicious. Examples of unexpected and potentially malicious events on mobile devices, particularly when they occur without specific user interaction, may include making phone calls, accessing or making changes to the contacts/phone book, accessing user habits such as browser settings/history and other communication logs, accessing files, accessing the camera and audio, and so forth.

Claims (34)

1. A method for securing a mobile device against malware, the method comprising:

monitoring a plurality of events caused by an application executing on a mobile device, the plurality of events occurring during execution of the application on the mobile device;

detecting a first event in the plurality of events having occurred during execution of the application, wherein the first event is an unexpected event, the unexpected event generated by an application executing on the mobile device while a user of the mobile device is not interacting with the application, and the unexpected event incurring a charge for a purchase to a billing account of the user;

evaluating the first event in a context of the mobile device to determine whether the first event is potentially unauthorized; and

when the first event is a potentially unauthorized event, presenting a warning to the user on the mobile device that the potentially unauthorized event has occurred, and requesting user confirmation that the potentially unauthorized event be allowed to continue.

2. The method of claim 1 , wherein the application controls a camera of the mobile device.

3. The method of claim 1 , wherein the application controls a microphone of the mobile device.

4. The method of claim 1 , wherein the application includes at least one of a communication application, a phone application, and an instant messaging application.

5. The method of claim 4 , wherein the first event is an instant message or a phone call incurring a charge to the user.

6. The method of claim 4 , wherein the first event includes a Uniform Resource Locator (URL) request.

7. The method of claim 1 , wherein the context includes one or more other events functionally associated with the first event.

8. The method of claim 1 , wherein the context includes one or more other events temporally associated with the first event.

9. The method of claim 1 , wherein the context includes a history of recent user interactions with the mobile device.

10. The method of claim 1 , wherein the context includes a history of recent user interactions with the application.

11. The method of claim 1 , wherein the first event includes access to one or more of a browsing history, personal contacts, and a communications log on the mobile device.

12. The method of claim 1 , wherein the context includes a time of the first event.

13. The method of claim 1 , wherein the context includes a reputation of the application.

14. The method of claim 13 , wherein the reputation is based on one or more of a popularity of the application, a reputation of a provider of the application, and an installed base of the application among a population of users.

15. The method of claim 1 , further comprising:

logging a time of the first event with a security application; wherein

evaluating whether the first event in a context of the mobile device to determine whether the first event is a potentially unauthorized event includes evaluating whether the time of the first event is different than other historical events associated with the user of the mobile device.

16. The method of claim 1 , wherein the context of the mobile device includes a comparison of an executed time of the first event to h istorically executed times for the first event.

17. A computer program product for securing a mobile device against malware, the computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on a mobile device, performs the steps of:

monitoring a plurality of events caused by an application executing on a mobile device, the plurality of events occurring during execution of the application on the mobile device;

detecting a first event in the plurality of events having occurred during execution of the application, wherein the first event is an unexpected event, the unexpected event generated by the application executing on the mobile device while a user of the mobile device is not interacting with the application, and the unexpected event incurring a charge for a purchase to a billing acount of the user;

evaluating the first event in a context of the mobile device to determine whether the first event is potentially unauthorized; and

when the first event is a potentially unauthorized event, presenting a warning to the user on the mobile device that the potentially unauthorized event has occurred.

18. A mobile device comprising:

a display;

a communications interface configured to couple the mobile device in a communicating relationship with a network;

a processor; and

a memory bearing computer code that, when executing on the processor, performs the steps of monitoring a plurality of events generated by an application executing on the mobile device, the plurality of event occurring during execution of the application on the mobile device; detecting a first event in the plurality of events having occurred during execution of the application, wherein the first event is an unexpected event, the unexpected event generated by the application executing on the mobile device while a user of the mobile device is not interacting with the application, and the unexpected event incurring a charge for a purchase to a billing account of the user; evaluating the first event in a context of the mobile device to determine whether the first event is potentially unauthorized; and when the first event is a potentially unauthorized event, presenting a warning to the user that the potentially unauthorized event has occurred.

19. The mobile device of claim 18 , wherein the mobile device is at least one of a smart phone and a tablet.

20. The mobile device of claim 18 , further comprising at least one of a camera and a microphone.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2019
From: MCDONALD, SEAN PATRICK
To: SOPHOS LIMITED
Reel/Frame 049193/0916 →
Continuity (2)
Continuation 15179547 · Jun 10, 2016
Related Publication 20190268302A1 · Aug 29, 2019
Cited By (8)
US 12,192,170 US 12,255,926 US 12,299,658 US 12,301,574 US 12,314,396 US 12,380,476 US 12,499,427 US 12,511,627